Incorrect permission assignment for critical resource in Harbor - #VU153946

 

Incorrect permission assignment for critical resource in Harbor - #VU153946

Published: October 7, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153946
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-732
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to read, modify, or delete resources across projects and take over project robot accounts, locking out their owners.

The vulnerability exists due to incorrect permission assignment in Harbor's system robot permission handling when processing project resource permissions with the cover all projects scope. A remote privileged user can exercise project read, update, or delete permissions as a global wildcard over resources inside every project, including changing robot permissions and resetting their secrets, to read, modify, or delete resources across projects and take over project robot accounts, locking out their owners.

Exploitation requires possession of a system robot account's token with the affected scope and project resource permissions. Robot accounts scoped to specific projects are not affected.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins